IP Library Granted Patent US 8,893,293
Granted Patent B1
US 8,893,293 · App. 13/844,622 · Granted Nov 18, 2014

Elevating trust in user identity during RESTful authentication

Inventors: Timothy Schmoyer (Harvard, MA); Michael Dufel (Manitou Springs, CO); David Staggs (Austin, TX); Vijayababu Subramanium (Columbia, SC)
Assignee: Jericho Systems Corporation
H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,893,293
App. No.
13/844,622
Granted
Nov 18, 2014
Kind
B1
Abstract

Credentials sent over a back channel during the authentication of a user to a RESTful service can elevate the trust the recipient system can place in the user's identity. The addition of an identity credential of higher strength can increase confidence in user identities electronically presented with a lower strength credential.

Claims (36)

1. A computer-implemented method of authenticating an entity, comprising:

receiving, by a RESTful service running on one or more processors, a request for authentication of an entity;

redirecting the authentication request to a relying party, wherein the relying party facilitates the authentication of the entity and stores a first credential and a back channel SAML credential;

receiving, by the RESTful service, the first credential from the relying party, wherein the first credential is received through a front channel;

receiving, by the RESTful service, the back channel SAML credential from the relying party, wherein the back channel SAML credential is received through a back channel; and

authenticating the entity at a level of confidence based on the credential strength of the first credential and the back channel SAML credential.

2. The method of claim 1 , wherein the relying party facilitates the authentication of the entity using an OpenID identity provider.

3. The method of claim 1 , wherein the back channel SAML assertion has the credential strength of DoDI 8520.03 level C.

4. The method of claim 1 , wherein the back channel SAML assertion has an SP 800-63 level of assurance 3.

5. The method of claim 1 , wherein the back channel SAML assertion has an SP 800-63 level of assurance 4.

6. The method of claim 1 , wherein the back channel SAML assertion passed by the relying party contains X.509 attributes.

7. The method of claim 1 , wherein information passed on the back channel is encrypted using SSL protocol.

8. The method of claim 1 , wherein information passed on the back channel is encrypted using TLS protocol.

9. The method of claim 1 , wherein information passed on the back channel is exchanged using SOAP protocol.

10. The method of claim 1 , wherein the first credential is a CAS credential.

11. A computer-implemented authentication system, comprising:

a RESTful service running on one or more processors and comprising an authentication component operable to:

receive a request for authentication of an entity using an entity agent,

redirect the entity agent to a relying party,

receive a first credential related to the authentication request, wherein the first credential is received from the relying party and through a front channel,

receive a back channel SAML credential related to the authentication request, wherein the back channel SAML credential is received from the relying party and through a back channel, and

authenticate the entity at a level of confidence based on the credential strength of the first credential and the back channel SAML credential;

a relying party operable to:

facilitate the authentication of the entity,

store the first credential and the back channel SAML credential,

send, through the front channel, the first credential to the authentication component, and

send, through the back channel, the back channel SAML credential to the authentication component.

12. The method of claim 11 , wherein the relying party is further operable to facilitate authentication by using an Open ID profile.

13. The method of claim 11 , wherein the back channel SAML assertion has the credential strength of DoDI 8520.03 level C.

14. The method of claim 11 , wherein the back channel SAML assertion has an SP 800-63 level of assurance 3.

15. The method of claim 11 , wherein the back channel SAML assertion has an SP 800-63 level of assurance 4.

16. The method of claim 11 , wherein the back channel SAML assertion contains X.509 attributes.

17. The method of claim 11 , wherein the relying party is further operable to encrypt the back channel using SSL protocol.

18. The method of claim 11 , wherein the relying party is further operable to encrypt the back channel using TLS protocol.

19. The method of claim 11 , wherein relying party is further operable to use SOAP protocol on the back channel.

20. The method of claim 11 , wherein the first credential is a CAS credential.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2021
From: BIN 2020, SERIES 550 ALLIED SECURITY TRUST I
To: CROWDSTRIKE, INC.
Reel/Frame 058310/0455 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2020
From: JERICHO SYSTEMS CORPORATION
To: BIN 2020, SERIES 550 OF ALLIED SECURITY TRUST I
Reel/Frame 052831/0119 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2014
From: SCHMOYER, TIMOTHY; DUFEL, MICHAEL; STAGGS, DAVID; SUBRAMANIUM, VIJAYABABU
To: JERICHO SYSTEMS CORPORATION
Reel/Frame 032140/0440 →
Continuity (1)
Provisional Application 61691248 · Aug 20, 2012